All vulnerabilities
1070 / 1070
Sort
9.8
CVE-2020-29583CVE KEV
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unc…
2020-01-01KEV
EPSS94.3%
pct 99
6.5
CVE-2024-9014ANC
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. T…
2024-01-01
EPSS92.9%
pct 99
9.8
CVE-2024-44000ANC
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache al…
2024-01-01Pre-auth
EPSS92.8%
pct 99
9.8
CVE-2017-9248CVE KEV
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity be…
2017-01-01KEV
EPSS89.4%
pct 99
9.8
CVE-2024-32238
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's managem…
2024-01-01Pre-auth
EPSS87.8%
pct 99
8.6
CVE-2022-1026CVE
Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose s…
2022-01-01Pre-auth
EPSS85.8%
pct 99
7.5
CVE-2014-6039CVE
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vu…
2014-01-01Pre-auth
EPSS83.6%
pct 99
6.5
CVE-2021-44451CVE
Apache Superset up to and including 1.3.2 allowed for registered database connections password …
2021-01-01
EPSS83.4%
pct 99
7.5
CVE-2023-6421CVE
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords,…
2023-01-01Pre-auth
EPSS82.4%
pct 99
9.8
CVE-2018-9160CVE
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
2018-01-01Pre-auth
EPSS74.2%
pct 98
9.8
CVE-2022-35411CVE
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializ…
2022-01-01Pre-auth
EPSS71.3%
pct 98
9.8
CVE-2017-8225CVE
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is n…
2017-01-01Pre-auth
EPSS58.5%
pct 98
9.8
CVE-2013-7055CVE
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
2013-01-01Pre-auth
EPSS56.7%
pct 98
9.8
CVE-2021-30116CVE KEV
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By…
2021-01-01KEV
EPSS54.1%
pct 98
9.8
CVE-2013-7052CVE
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
2013-01-01Pre-auth
EPSS50.4%
pct 97
9.8
CVE-2014-5381CVE
Grand MA 300 allows a brute-force attack on the PIN.
2014-01-01Pre-auth
EPSS46.4%
pct 97
6.5
CVE-2022-38121CVE
UPSMON PRO configuration file stores user password in plaintext under public user directory. A …
2022-01-01
EPSS44.3%
pct 97
9.8
CVE-2022-28005CVE
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3…
2022-01-01Pre-auth
EPSS38.2%
pct 97
7.5
CVE-2020-5260AST
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private c…
2020-01-01Pre-auth
EPSS37.3%
pct 97
9.8
CVE-2018-11742CVE
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
2018-01-01Pre-auth
EPSS36.4%
pct 97
7.5
CVE-2019-19823CVE
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc2…
2019-01-01Pre-auth
EPSS28.7%
pct 96
9.8
CVE-2017-3192CVE
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently prot…
2017-01-01Pre-auth
EPSS27.7%
pct 96
5.9
CVE-2021-29262DEB
When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMP…
2021-01-01Pre-auth
EPSS26.2%
pct 96
9.8
CVE-2017-17106CVE
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated …
2017-01-01Pre-auth
EPSS25.1%
pct 96
7.5
CVE-2012-6663CVE
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
2012-01-01Pre-auth
EPSS23.1%
pct 96
9.8
CVE-2025-25570
Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded c…
2025-01-01Pre-auth
EPSS20.6%
pct 95
8.8
CVE-2021-43397CVE
LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or Use…
2021-01-01
EPSS18.3%
pct 95
9.8
CVE-2021-22681CVE KEV
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions…
2021-01-01KEV
EPSS18.2%
pct 95
7.5
CVE-2024-23733
The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMe…
2024-01-01Pre-auth
EPSS18.1%
pct 95
8.1
CVE-2018-3609CVE
A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 m…
2018-01-01Pre-auth
EPSS16.3%
pct 94
9.8
CVE-2018-19466CVE
A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corres…
2018-01-01Pre-auth
EPSS12.8%
pct 94
9.8
CVE-2014-5093CVE
Status2k does not remove the install directory allowing credential reset.
2014-01-01Pre-auth
EPSS12.2%
pct 93
9.8
CVE-2017-8837CVE
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices…
2017-01-01Pre-auth
EPSS11.0%
pct 93
4.6
CVE-2024-44815CVE
Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attack…
2024-01-01
EPSS10.8%
pct 93
9.8
CVE-2000-0944CVE
CGI Script Center News Update 1.1 does not properly validate the original news administration p…
2000-01-01Pre-auth
EPSS10.7%
pct 93
9.8
CVE-2022-4693CVE
The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vu…
2022-01-01Pre-auth
EPSS10.2%
pct 93
4.4
CVE-2018-20781AST
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a sessio…
2018-01-01
EPSS9.9%
pct 93
7.5
CVE-2023-30846CVE
typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScr…
2023-01-01Pre-auth
EPSS9.1%
pct 92
8.8
CVE-2022-29457CVE
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701…
2022-01-01
EPSS8.3%
pct 92
6.5
CVE-2021-42306CVE
An information disclosure vulnerability manifests when a user or an application uploads unprote…
2021-01-01
EPSS8.2%
pct 92
Select a vulnerability on the left to open the preview.